A simple and effective way of erasing the CodeRed malware #CodeRed antivirus #CodeRed remover #Worm cleaner #CodeRed #Antivirus #Remover
CodeRed Detection and Removal Tool is a lightweight utility that targets the Win32.IISWorm.CodeRed.F worm.
The virus exploits a buffer overflow vulnerability in the Microsoft Windows IIS Server, that runs on Microsoft Windows NT and Windows 2000. The patch and information about this problem can be found at the address:
http://www.microsoft.com/technet/security/bulletin/MS01-033.asp
The worm begins spreading itself by sending HTTP queries. Unpatched machines will execute the worm code directly from memory. Once executed, the worm scans kernel32.dll 's export table for the GetProcAddress function and then finds the addresses of the functions needed for further spreading. It then exploits yet another bug in Microsoft Windows, the relative shell path vulnerability.
This particular vulnerability is used to load another shell program instead of the usual explorer.exe (found in %WINDIR%) by writing a file named explorer.exe in the %SYSTEMROOT% directory. The worm checks whether Chinese (either Traditional or Simplified) is the language installed on the system. If it is Chinese, it creates 600 threads and spreads for 48hours. On a non-Chinese system it creates 300 threads and spreads for 24 hours.
After that, it reboots the system using ExitWindowEx function. The worm dumps part of its body to %SYSTEMROOT%explorer.exe, which is in fact a trojan component, allowing the attacker to remotely access the infected computers.
The trojan component modifies the registry key:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable]
to disable file system security and allows a remote attacker to access drives C: and D: via a web browser by adding read/write rights using the registry key:
[HKLM\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots]
CodeRed Detection and Removal Tool 1.0.0.115
add to watchlist add to download basket send us an update REPORT- runs on:
-
Windows NT
Windows 7
Windows Vista
Windows 2K - file size:
- 31 KB
- filename:
- codered.zip
- main category:
- Antivirus
- developer:
- visit homepage
Windows Sandbox Launcher
Bitdefender Antivirus Free
IrfanView
ShareX
Microsoft Teams
4k Video Downloader
calibre
Context Menu Manager
Zoom Client
7-Zip
- Context Menu Manager
- Zoom Client
- 7-Zip
- Windows Sandbox Launcher
- Bitdefender Antivirus Free
- IrfanView
- ShareX
- Microsoft Teams
- 4k Video Downloader
- calibre